07-27-2018 05:24 AM - edited 03-08-2019 03:46 PM
Hi, We are currently working on a migration of systems from our traditional network (VLAN's, STP etc.) to a third party hosting company running VXlan, overlay networks.
Unfortunately we have to maintain the existing IP space so extending l2 broadcast domain for each VLAN, to achieve this we will be cabling into our 2960x switch stacks (2gb ether-channels). To protect ourselves we will be specifying on the third party connected ports the allowed VLAN's, disabling cdp and setting storm control to a value of 10, to configure the backup link and ensure it doesn't become STP root we will be setting port-priority to 192 and VLAN cost to 24 for each of the migrating VLAN's.
As we have little experience of VXlan's we don't know if there is anything else we need to be aware of when connecting the two networks to ensure we protect our network.
Thank you in advance
Cheers
Solved! Go to Solution.
07-27-2018 07:00 AM
Hi, the separation is done by the protocol. The provider will use a S-VLAN to "transport" your C-VLAN. You have configured the right policies to protect your network so you should not have problems.
Regards.
07-27-2018 07:00 AM
Hi, the separation is done by the protocol. The provider will use a S-VLAN to "transport" your C-VLAN. You have configured the right policies to protect your network so you should not have problems.
Regards.
07-29-2018 04:53 PM
Thank you very much for your prompt response and reassurance that we are on the right track to protecting ourselves.
Cheers
Nick
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide